-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[pull] master from cert-manager:master #1066
base: master
Are you sure you want to change the base?
Commits on Jul 4, 2024
-
add design for pushing charts to OCI registry
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 38b7021 - Browse repository at this point
Copy the full SHA 38b7021View commit details -
tweak design to push to quay.io/jetstack/charts
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for bccdb05 - Browse repository at this point
Copy the full SHA bccdb05View commit details -
Merge pull request #7155 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 659f22b - Browse repository at this point
Copy the full SHA 659f22bView commit details -
changed the scorecard badge link to the standard format
Signed-off-by: harshitasao <harshitasao@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 9cfe0bc - Browse repository at this point
Copy the full SHA 9cfe0bcView commit details
Commits on Jul 10, 2024
-
Reduce memory usage by only caching the metadata of Secret resources
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 8f9ccf3 - Browse repository at this point
Copy the full SHA 8f9ccf3View commit details -
Configuration menu - View commit details
-
Copy full SHA for 15084fd - Browse repository at this point
Copy the full SHA 15084fdView commit details -
Update the memory-management design document
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 961e81b - Browse repository at this point
Copy the full SHA 961e81bView commit details -
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 8c182d7 - Browse repository at this point
Copy the full SHA 8c182d7View commit details -
Configuration menu - View commit details
-
Copy full SHA for c96e6a6 - Browse repository at this point
Copy the full SHA c96e6a6View commit details -
Updating the badge link to the new domain
Signed-off-by: harshitasao <harshitasao@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for aaad3b9 - Browse repository at this point
Copy the full SHA aaad3b9View commit details
Commits on Jul 12, 2024
-
Merge pull request #7161 from wallrj/7147-cainjector-metadata-only-cache
Reduce memory usage by only caching the metadata of Secret resources
Configuration menu - View commit details
-
Copy full SHA for c746fdf - Browse repository at this point
Copy the full SHA c746fdfView commit details -
Merge pull request #7108 from inteon/bugfix_aws
BUGFIX: AWS route53: Set global region for sts
Configuration menu - View commit details
-
Copy full SHA for 4e3c162 - Browse repository at this point
Copy the full SHA 4e3c162View commit details
Commits on Jul 15, 2024
-
Allow config of http01 solver pod security context
This allows configuration of the http01 solver PodSecurityContext as part of the Issuer specification. Signed-off-by: Adrian Lai <aidy@loathe.me.uk>
Configuration menu - View commit details
-
Copy full SHA for 3e98f55 - Browse repository at this point
Copy the full SHA 3e98f55View commit details -
Generate CRDs / conversion functions
Signed-off-by: Adrian Lai <aidy@loathe.me.uk>
Configuration menu - View commit details
-
Copy full SHA for 12e3233 - Browse repository at this point
Copy the full SHA 12e3233View commit details -
Add test for http01 PodSecurityContext config
Signed-off-by: Adrian Lai <aidy@loathe.me.uk>
Configuration menu - View commit details
-
Copy full SHA for 96831b9 - Browse repository at this point
Copy the full SHA 96831b9View commit details -
Configuration menu - View commit details
-
Copy full SHA for 62bdee8 - Browse repository at this point
Copy the full SHA 62bdee8View commit details -
Update/Fix tests for new test structure
Signed-off-by: Adrian Lai <adrian.lai@jetstack.io>
Configuration menu - View commit details
-
Copy full SHA for 8b68443 - Browse repository at this point
Copy the full SHA 8b68443View commit details -
Copy PodSecurityContext over, dropping windowsOptions
Signed-off-by: Adrian Lai <adrian.lai@jetstack.io>
Configuration menu - View commit details
-
Copy full SHA for 6dc80e5 - Browse repository at this point
Copy the full SHA 6dc80e5View commit details -
These were copy-pasted in from the parent definitions. We don't marshal to protobuf (none of the other structs have equivalent annotations), so remove them as they are unnecessary. Signed-off-by: Adrian Lai <adrian.lai@jetstack.io>
Configuration menu - View commit details
-
Copy full SHA for bde1acd - Browse repository at this point
Copy the full SHA bde1acdView commit details -
fix: Handle case of Azure returning auth error
Signed-off-by: Bartosz Slawianowski <bartosz.slawianowski@natzka.com>
Configuration menu - View commit details
-
Copy full SHA for cb2731e - Browse repository at this point
Copy the full SHA cb2731eView commit details
Commits on Jul 16, 2024
-
test: adds test for getHTTPRouteForChallenge
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for c989dfd - Browse repository at this point
Copy the full SHA c989dfdView commit details -
fix: checkAndUpdateGatewayHTTPRoute function
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 937fc85 - Browse repository at this point
Copy the full SHA 937fc85View commit details -
test: add test for ensureGatewayHTTPRoute
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 35e5e12 - Browse repository at this point
Copy the full SHA 35e5e12View commit details -
Signed-off-by: Bartosz Slawianowski <bartosz.slawianowski@natzka.com>
Configuration menu - View commit details
-
Copy full SHA for 30d4fce - Browse repository at this point
Copy the full SHA 30d4fceView commit details -
test: add test for multiple httproute resources
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for dc100b4 - Browse repository at this point
Copy the full SHA dc100b4View commit details
Commits on Jul 17, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9eeeabd - Browse repository at this point
Copy the full SHA 9eeeabdView commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d673563 - Browse repository at this point
Copy the full SHA d673563View commit details -
Merge pull request #7171 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for b77411b - Browse repository at this point
Copy the full SHA b77411bView commit details -
test: check for httproute clean-up
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 7677258 - Browse repository at this point
Copy the full SHA 7677258View commit details -
fix: add missing hyphen to generateName
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 8ffe264 - Browse repository at this point
Copy the full SHA 8ffe264View commit details -
fix: httproute spec deep equal
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 8d2aac9 - Browse repository at this point
Copy the full SHA 8d2aac9View commit details -
run 'make upgrade-klone' and 'make generate'
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d3a2ad9 - Browse repository at this point
Copy the full SHA d3a2ad9View commit details -
Merge pull request #7180 from inteon/upgrade_makefiles
Run 'make upgrade-klone' and 'make generate'
Configuration menu - View commit details
-
Copy full SHA for bfbe9fb - Browse repository at this point
Copy the full SHA bfbe9fbView commit details -
revert: remove override for generate name
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for f357097 - Browse repository at this point
Copy the full SHA f357097View commit details
Commits on Jul 18, 2024
-
fix: do not present challenge for Gateway API if feature not enabled
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 8a8df8a - Browse repository at this point
Copy the full SHA 8a8df8aView commit details -
fix: add boilerplate to test file
Signed-off-by: Miguel Varela Ramos <miguel@cohere.ai>
Configuration menu - View commit details
-
Copy full SHA for 46f3f04 - Browse repository at this point
Copy the full SHA 46f3f04View commit details -
Run 'make upgrade-klone' and 'make generate'
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9770794 - Browse repository at this point
Copy the full SHA 9770794View commit details -
Merge pull request #7185 from cert-manager/self-upgrade-master
[CI] Self-upgrade merging self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for aba3f6a - Browse repository at this point
Copy the full SHA aba3f6aView commit details -
Merge pull request #7178 from miguelvr/miguelvr/http01-gw-solver-tests
fix: HTTP01 challenge HTTPRoute creation for GatewayAPI
Configuration menu - View commit details
-
Copy full SHA for 17e883c - Browse repository at this point
Copy the full SHA 17e883cView commit details -
Merge pull request #7177 from eplightning/fix-azure-npe
fix: Handle case of Azure returning auth error
Configuration menu - View commit details
-
Copy full SHA for 5f003f2 - Browse repository at this point
Copy the full SHA 5f003f2View commit details
Commits on Jul 19, 2024
-
Fix incorrect indentation of the PodMonitor template in the Helm chart
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for c5e95aa - Browse repository at this point
Copy the full SHA c5e95aaView commit details -
Merge pull request #7190 from wallrj/fix-podmonitor-template-indentation
Fix incorrect indentation of the PodMonitor template in the Helm chart
Configuration menu - View commit details
-
Copy full SHA for fc198e9 - Browse repository at this point
Copy the full SHA fc198e9View commit details -
Enable metrics server on the webhook
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for e21a57a - Browse repository at this point
Copy the full SHA e21a57aView commit details
Commits on Jul 23, 2024
-
Merge pull request #7182 from wallrj/7065-webhook-metrics
[VC-34401] Add a metrics server to the webhook
Configuration menu - View commit details
-
Copy full SHA for e1c1927 - Browse repository at this point
Copy the full SHA e1c1927View commit details -
Add metrics server to the cainjector
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 4cec43b - Browse repository at this point
Copy the full SHA 4cec43bView commit details -
Configuration menu - View commit details
-
Copy full SHA for 4861579 - Browse repository at this point
Copy the full SHA 4861579View commit details -
Add metrics configuration to the cainjector templates of the Helm chart
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 9273158 - Browse repository at this point
Copy the full SHA 9273158View commit details -
Fix the podAnnotations check in the metrics labels section of the web…
…hook deployment Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for b6c8c34 - Browse repository at this point
Copy the full SHA b6c8c34View commit details
Commits on Jul 24, 2024
-
Merge pull request #7194 from wallrj/7065-cainjector-metrics
[VC-34401] Add a metrics server to the cainjector
Configuration menu - View commit details
-
Copy full SHA for f2b1af6 - Browse repository at this point
Copy the full SHA f2b1af6View commit details -
Update the Google CloudBuild job image
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 355d6af - Browse repository at this point
Copy the full SHA 355d6afView commit details -
Merge pull request #7199 from wallrj/update-google-cloudbuild-image
Update the Google CloudBuild job image
Configuration menu - View commit details
-
Copy full SHA for 3e83d22 - Browse repository at this point
Copy the full SHA 3e83d22View commit details
Commits on Jul 26, 2024
-
error out ACME Challenges when encountering non-ACME errors
Signed-off-by: Brian Dols <brian.dols@inky.com>
Configuration menu - View commit details
-
Copy full SHA for dc0295c - Browse repository at this point
Copy the full SHA dc0295cView commit details
Commits on Jul 30, 2024
-
Update pkg/issuer/venafi/client/venaficlient.go
Co-authored-by: Richard Wall <wallrj@users.noreply.github.com> Signed-off-by: Peter Fiddes <hawksight@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 883e41b - Browse repository at this point
Copy the full SHA 883e41bView commit details -
Update pkg/issuer/venafi/client/venaficlient.go
Co-authored-by: Richard Wall <wallrj@users.noreply.github.com> Signed-off-by: Peter Fiddes <hawksight@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 5cabc54 - Browse repository at this point
Copy the full SHA 5cabc54View commit details -
chore: Update deps in venafclient.go to match gci formatting
Signed-off-by: Peter Fiddes <peter.fiddes@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 527477b - Browse repository at this point
Copy the full SHA 527477bView commit details
Commits on Jul 31, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0a33e64 - Browse repository at this point
Copy the full SHA 0a33e64View commit details -
Merge pull request #7205 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 9e9c43f - Browse repository at this point
Copy the full SHA 9e9c43fView commit details -
chore: Update deps in venafclient.go to match gci custom formatting
Signed-off-by: Peter Fiddes <peter.fiddes@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 134f498 - Browse repository at this point
Copy the full SHA 134f498View commit details
Commits on Aug 5, 2024
-
Merge pull request #5373 from aidy/set-security-context
Allow config of http01 solver pod security context
Configuration menu - View commit details
-
Copy full SHA for e65c363 - Browse repository at this point
Copy the full SHA e65c363View commit details -
feat: allow pod template to be specified when using gateway-api
Signed-off-by: Adam Talbot <adam.talbot@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 107a82c - Browse repository at this point
Copy the full SHA 107a82cView commit details
Commits on Aug 6, 2024
-
Merge pull request #7211 from ThatsMrTalbot/feat/gateway-api-pod-temp…
…late feat: allow pod template to be specified when using gateway-api
Configuration menu - View commit details
-
Copy full SHA for 1a68058 - Browse repository at this point
Copy the full SHA 1a68058View commit details
Commits on Aug 7, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 46dd542 - Browse repository at this point
Copy the full SHA 46dd542View commit details -
Merge pull request #7215 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 4640f4f - Browse repository at this point
Copy the full SHA 4640f4fView commit details
Commits on Aug 8, 2024
-
fix: update shasum for docker.io/ubuntu/bind9
Signed-off-by: Adam Talbot <adam.talbot@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 1362429 - Browse repository at this point
Copy the full SHA 1362429View commit details -
Merge pull request #7219 from ThatsMrTalbot/fix/bind9-shasum-update
fix: update shasum for docker.io/ubuntu/bind9
Configuration menu - View commit details
-
Copy full SHA for 7253d0b - Browse repository at this point
Copy the full SHA 7253d0bView commit details -
Add RBAC for the serviceaccount to create tokens
When creating the cert-manager serviceaccount we should include the RBAC permissions to create serviceaccount tokens, which are required when using the incuded serviceaccount for authenticating against AWS IRSA when configuring Route53. This aligns with the documentation on Route53, where these permissions are only to be created manually when using a different serviceaccount. Other usecases may apply as well. Fixes #7212 Signed-off-by: Jasper Orschulko <jasper@fancydomain.eu>
Configuration menu - View commit details
-
Copy full SHA for 8dea2d0 - Browse repository at this point
Copy the full SHA 8dea2d0View commit details -
add timeout for ACME WaitAuthorization
Signed-off-by: Brian Dols <brian.dols@inky.com>
Configuration menu - View commit details
-
Copy full SHA for 4176a7b - Browse repository at this point
Copy the full SHA 4176a7bView commit details
Commits on Aug 11, 2024
-
fix errcheck linter by adding error checks everywhere
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 14eb9f5 - Browse repository at this point
Copy the full SHA 14eb9f5View commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b0714bc - Browse repository at this point
Copy the full SHA b0714bcView commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for e466446 - Browse repository at this point
Copy the full SHA e466446View commit details -
use utilruntime.Must to reduce amount of unnecessary if-else code whe…
…n registering schemes Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 112beae - Browse repository at this point
Copy the full SHA 112beaeView commit details
Commits on Aug 12, 2024
-
add comments and make the timeout value a const
Signed-off-by: Brian Dols <brian.dols@inky.com>
Configuration menu - View commit details
-
Copy full SHA for 58fec28 - Browse repository at this point
Copy the full SHA 58fec28View commit details -
Configuration menu - View commit details
-
Copy full SHA for f3b1506 - Browse repository at this point
Copy the full SHA f3b1506View commit details -
make the policy results more consitent (sorting map keys) and clearly…
… seperate checking the label/annot. values vs checking the label/annot. keys Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2295472 - Browse repository at this point
Copy the full SHA 2295472View commit details -
add fuzz test for vault issuer
Signed-off-by: Adam Korczynski <adam@adalogics.com>
Configuration menu - View commit details
-
Copy full SHA for 772f333 - Browse repository at this point
Copy the full SHA 772f333View commit details
Commits on Aug 13, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9809537 - Browse repository at this point
Copy the full SHA 9809537View commit details -
Merge pull request #7228 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 7f1e02f - Browse repository at this point
Copy the full SHA 7f1e02fView commit details
Commits on Aug 14, 2024
-
add caRequiresRegeneration unit test and fix incorrect renewal time c…
…alculation Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 65aea19 - Browse repository at this point
Copy the full SHA 65aea19View commit details -
add test case for expired certificate
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 8844fd3 - Browse repository at this point
Copy the full SHA 8844fd3View commit details -
Merge pull request #7230 from inteon/bugfix_dynamic_authority
BUGFIX: fix incorrect tls server renewal time check and add unit tests
Configuration menu - View commit details
-
Copy full SHA for 2472ccf - Browse repository at this point
Copy the full SHA 2472ccfView commit details -
Signed-off-by: Brian Dols <brian.dols@inky.com>
Configuration menu - View commit details
-
Copy full SHA for 9195a5d - Browse repository at this point
Copy the full SHA 9195a5dView commit details -
Merge pull request #7202 from bdols/non-acme-error
error out ACME Challenges when encountering non-ACME errors
Configuration menu - View commit details
-
Copy full SHA for 138235c - Browse repository at this point
Copy the full SHA 138235cView commit details -
Merge pull request #7150 from inteon/fix_errcheck
Fix errcheck linter by adding error checks everywhere
Configuration menu - View commit details
-
Copy full SHA for e3b2387 - Browse repository at this point
Copy the full SHA e3b2387View commit details -
clarify mapsHaveMatchingValues comment
Co-authored-by: Ashley Davis <SgtCoDFish@users.noreply.github.com> Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 233cfbc - Browse repository at this point
Copy the full SHA 233cfbcView commit details
Commits on Aug 15, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 44f33a0 - Browse repository at this point
Copy the full SHA 44f33a0View commit details -
Merge pull request #7233 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for b01a834 - Browse repository at this point
Copy the full SHA b01a834View commit details
Commits on Aug 16, 2024
-
Run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com> aaaaaaaaaa
Configuration menu - View commit details
-
Copy full SHA for 2b736f5 - Browse repository at this point
Copy the full SHA 2b736f5View commit details -
upgrade k8s.io and c/r deps and fix breaking changes
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 06fdf1d - Browse repository at this point
Copy the full SHA 06fdf1dView commit details -
add temporary golangci-lint exceptions
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0c38de4 - Browse repository at this point
Copy the full SHA 0c38de4View commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7835b03 - Browse repository at this point
Copy the full SHA 7835b03View commit details
Commits on Aug 17, 2024
-
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 98d8766 - Browse repository at this point
Copy the full SHA 98d8766View commit details
Commits on Aug 20, 2024
-
Merge pull request #7237 from cert-manager/self-upgrade-master
Run 'make upgrade-klone' and 'make generate'
Configuration menu - View commit details
-
Copy full SHA for 44d6b14 - Browse repository at this point
Copy the full SHA 44d6b14View commit details -
Merge pull request #7227 from inteon/sort_annotations_and_labels
Improve ordering consistency of policy chain results (issuance, ready ...)
Configuration menu - View commit details
-
Copy full SHA for 0557657 - Browse repository at this point
Copy the full SHA 0557657View commit details -
add unit tests for tls authority logic and improve logs
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 45a52cc - Browse repository at this point
Copy the full SHA 45a52ccView commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for ae491bf - Browse repository at this point
Copy the full SHA ae491bfView commit details
Commits on Aug 21, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c3621f0 - Browse repository at this point
Copy the full SHA c3621f0View commit details -
Merge pull request #7241 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for c7f61ed - Browse repository at this point
Copy the full SHA c7f61edView commit details -
apply changes suggested by review
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 142a06f - Browse repository at this point
Copy the full SHA 142a06fView commit details -
fix staticcheck: replace deprecated function calls
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 3125e66 - Browse repository at this point
Copy the full SHA 3125e66View commit details -
Merge pull request #7213 from Jasper-Ben/add_serviceaccount_token_rbac
Add RBAC for the serviceaccount to create tokens
Configuration menu - View commit details
-
Copy full SHA for d3124ac - Browse repository at this point
Copy the full SHA d3124acView commit details -
use types.NamespacedName in typed queue
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 6348a68 - Browse repository at this point
Copy the full SHA 6348a68View commit details -
Merge pull request #7242 from inteon/linter_fix
Fix staticcheck linter: use types.NamespacedName in workqueue
Configuration menu - View commit details
-
Copy full SHA for 01a107f - Browse repository at this point
Copy the full SHA 01a107fView commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2747726 - Browse repository at this point
Copy the full SHA 2747726View commit details -
re-enable usestdlibvars linter
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 5951ac4 - Browse repository at this point
Copy the full SHA 5951ac4View commit details -
fully enable staticcheck linter
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c1f0a13 - Browse repository at this point
Copy the full SHA c1f0a13View commit details
Commits on Aug 23, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for be8e721 - Browse repository at this point
Copy the full SHA be8e721View commit details -
Merge pull request #7245 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for fc08cbc - Browse repository at this point
Copy the full SHA fc08cbcView commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 5821ede - Browse repository at this point
Copy the full SHA 5821edeView commit details -
In prometheus/client_golang#1424, a new check was introduced to make …
…sure the metric with the provided metricName is found. We were depending on it not erroring. This PR removes that assumption and instead makes sure the metric does no longer existi using the CollectAndCount function. Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d140d14 - Browse repository at this point
Copy the full SHA d140d14View commit details -
Merge pull request #7238 from inteon/goupgrade
Upgrade all go dependencies
Configuration menu - View commit details
-
Copy full SHA for e9799a8 - Browse repository at this point
Copy the full SHA e9799a8View commit details -
Run 'make upgrade-klone' and 'make generate'
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d71b087 - Browse repository at this point
Copy the full SHA d71b087View commit details -
Merge pull request #7246 from cert-manager/self-upgrade-master
[CI] Self-upgrade merging self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for f1a698b - Browse repository at this point
Copy the full SHA f1a698bView commit details
Commits on Aug 26, 2024
-
Merge pull request #7229 from inteon/authority_bugfix
Add unit tests for tls authority logic
Configuration menu - View commit details
-
Copy full SHA for 7d797a4 - Browse repository at this point
Copy the full SHA 7d797a4View commit details
Commits on Aug 29, 2024
-
RFC 5280 - Section 4.2.1.3 states that 'When the keyUsage extension a…
…ppears in a certificate, at least one of the bits MUST be set to 1.', we must thus ommit the KeyUsages extension when it does not have any KeyUsages set Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7e36193 - Browse repository at this point
Copy the full SHA 7e36193View commit details
Commits on Aug 30, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0449eba - Browse repository at this point
Copy the full SHA 0449ebaView commit details -
Merge pull request #7253 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for e9b2678 - Browse repository at this point
Copy the full SHA e9b2678View commit details
Commits on Sep 5, 2024
-
change message to a generic one
Signed-off-by: Adam Korczynski <adam@adalogics.com>
Configuration menu - View commit details
-
Copy full SHA for db04694 - Browse repository at this point
Copy the full SHA db04694View commit details
Commits on Sep 6, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 46ea393 - Browse repository at this point
Copy the full SHA 46ea393View commit details -
Merge pull request #7257 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 7d75c98 - Browse repository at this point
Copy the full SHA 7d75c98View commit details -
Configuration menu - View commit details
-
Copy full SHA for ba4ef85 - Browse repository at this point
Copy the full SHA ba4ef85View commit details -
Prevent aggressive Route53 retries caused by STS authentication failu…
…res by removing the Amazon Request ID from STS errors Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for da12061 - Browse repository at this point
Copy the full SHA da12061View commit details -
Merge pull request #7259 from wallrj/5486-redact-amz-request-id
Prevent aggressive Route53 retries caused by STS authentication failures by removing the Amazon Request ID from STS errors
Configuration menu - View commit details
-
Copy full SHA for 0395fd6 - Browse repository at this point
Copy the full SHA 0395fd6View commit details
Commits on Sep 9, 2024
-
Merge pull request #7192 from AdamKorcz/fuzz-july1
add fuzz test for cert requests with vault issuer
Configuration menu - View commit details
-
Copy full SHA for 7c808f8 - Browse repository at this point
Copy the full SHA 7c808f8View commit details
Commits on Sep 10, 2024
-
Merge pull request #7250 from inteon/only_add_keyusages_if_non_zero
BUGFIX: adhere to RFC 5280 - Section 4.2.1.3 and don't include empty KeyUsages extensions
Configuration menu - View commit details
-
Copy full SHA for 05cf58f - Browse repository at this point
Copy the full SHA 05cf58fView commit details
Commits on Sep 11, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 10bf033 - Browse repository at this point
Copy the full SHA 10bf033View commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 4cf366f - Browse repository at this point
Copy the full SHA 4cf366fView commit details -
Merge pull request #7265 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for b9cc814 - Browse repository at this point
Copy the full SHA b9cc814View commit details
Commits on Sep 12, 2024
-
remove empty apiGroup from 'subjects.ServiceAccount' refs
Signed-off-by: Yuedong Wu <dwcn22@outlook.com>
Configuration menu - View commit details
-
Copy full SHA for 64f8ad8 - Browse repository at this point
Copy the full SHA 64f8ad8View commit details -
fix SHA for bind image which changed upstream
also removes some trailing whitespace Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 609fd0b - Browse repository at this point
Copy the full SHA 609fd0bView commit details -
Merge pull request #7271 from SgtCoDFish/bindsha
fix SHA for bind image which changed upstream
Configuration menu - View commit details
-
Copy full SHA for 2b73ff6 - Browse repository at this point
Copy the full SHA 2b73ff6View commit details -
Merge pull request #7270 from lunarwhite/rm-empty
Helm: Remove empty apiGroup from 'subjects.ServiceAccount' refs
Configuration menu - View commit details
-
Copy full SHA for 3cc9320 - Browse repository at this point
Copy the full SHA 3cc9320View commit details
Commits on Sep 17, 2024
-
add fuzzer for venafi cr controller
Signed-off-by: Adam Korczynski <adam@adalogics.com>
Configuration menu - View commit details
-
Copy full SHA for 77b3df7 - Browse repository at this point
Copy the full SHA 77b3df7View commit details -
Merge pull request #7159 from harshitasao/scorecard-badge-link
changed the scorecard badge link to the standard format
Configuration menu - View commit details
-
Copy full SHA for 2202275 - Browse repository at this point
Copy the full SHA 2202275View commit details
Commits on Sep 18, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 6cba631 - Browse repository at this point
Copy the full SHA 6cba631View commit details -
Merge pull request #7281 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 1e332e2 - Browse repository at this point
Copy the full SHA 1e332e2View commit details -
Merge pull request #7279 from AdamKorcz/venafi-fuzzer
add fuzzer for venafi cr controller
Configuration menu - View commit details
-
Copy full SHA for 6d2f5e1 - Browse repository at this point
Copy the full SHA 6d2f5e1View commit details -
add further text explaining why we use an old license year
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 11a013b - Browse repository at this point
Copy the full SHA 11a013bView commit details -
Merge pull request #7283 from SgtCoDFish/license-year
Add further text explaining why we use an old license year
Configuration menu - View commit details
-
Copy full SHA for e1fb0c4 - Browse repository at this point
Copy the full SHA e1fb0c4View commit details -
Clarify how to use the Kind section of the PR template
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 26f3314 - Browse repository at this point
Copy the full SHA 26f3314View commit details -
Merge pull request #7280 from jsoref/improve-kind-discoverability
Clarify how to use the Kind section of the PR template
Configuration menu - View commit details
-
Copy full SHA for c69e9ba - Browse repository at this point
Copy the full SHA c69e9baView commit details -
Fix config api defaults updated messages
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for de85bd7 - Browse repository at this point
Copy the full SHA de85bd7View commit details -
Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 6564f1c - Browse repository at this point
Copy the full SHA 6564f1cView commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d52fd2f - Browse repository at this point
Copy the full SHA d52fd2fView commit details -
Merge pull request #7084 from hawksight/user-pass-oauth
feat: Use OAuth endpoint for Venafi Issuer when user/pass provided
Configuration menu - View commit details
-
Copy full SHA for c992382 - Browse repository at this point
Copy the full SHA c992382View commit details -
Add support for domain qualified finalizer
K8s expects finalizers to be of the form: FQDN/finalizer-name As such, the initial finalizer name (finalizer.acme.cert-manager.io) used by cert-manager is noncompliant. These changes add initial support for a proper domain qualified name (acme.cert-manager.io/finalizer). Support for using that new name will be added later. Feature plan: 1. Add support for tolerating the domain-qualified-finalizer 2. Add flag enabled support for setting the domain-qualified-finalizer 3. Release a version with current finalizer on by default 4. Change default behavior to use the domain-qualified-finalizer and allowing flag to use legacy behavior 5. Release a version with domain-qualified-finalizer on by default 6. Remove support for the legacy finalizer and the flag 7. Release a version with only domain-qualified-finalizer Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 0afe4ab - Browse repository at this point
Copy the full SHA 0afe4abView commit details -
Add feature gate for domain qualified finalizer
Ideally this allows users to use acme.cert-manager.io/finalizer Signed-off-by: Josh Soref <2119212+jsoref@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 4d97c4c - Browse repository at this point
Copy the full SHA 4d97c4cView commit details -
Merge pull request #7104 from Guitarkalle/6898-add-validity-duration-…
…to-venafi-certs 6898: Add validity duration to Venafi certificates
Configuration menu - View commit details
-
Copy full SHA for b127b55 - Browse repository at this point
Copy the full SHA b127b55View commit details -
Merge pull request #7273 from jsoref/issue-7266
Support a domain qualified finalizer instead of one that triggers a warning from kubernetes
Configuration menu - View commit details
-
Copy full SHA for bbb21d5 - Browse repository at this point
Copy the full SHA bbb21d5View commit details -
Merge pull request #7132 from SgtCoDFish/chartmigration
Add design for pushing charts to OCI registry
Configuration menu - View commit details
-
Copy full SHA for a7bff69 - Browse repository at this point
Copy the full SHA a7bff69View commit details -
remove issuer argument from CleanUp function, since it might no longe…
…r exist at the moment of deletion Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 40fd166 - Browse repository at this point
Copy the full SHA 40fd166View commit details -
add missing data to fake Challenges in tests
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for e184d1b - Browse repository at this point
Copy the full SHA e184d1bView commit details
Commits on Sep 19, 2024
-
simplify helper functions and add comments
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for f62e5e1 - Browse repository at this point
Copy the full SHA f62e5e1View commit details -
Merge pull request #7285 from inteon/remove_cleanup_argument
Remove issuer argument from CleanUp function
Configuration menu - View commit details
-
Copy full SHA for ced378b - Browse repository at this point
Copy the full SHA ced378bView commit details -
Test that Route53 region is optional
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for d369f92 - Browse repository at this point
Copy the full SHA d369f92View commit details -
Allow the Route53 region to be optional
Remove webhook validation for Route53 region Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 78a8391 - Browse repository at this point
Copy the full SHA 78a8391View commit details -
Merge pull request #7243 from inteon/linter_fix2
Enable and fix usestdlibvars, misspell and staticcheck linters
Configuration menu - View commit details
-
Copy full SHA for 060354a - Browse repository at this point
Copy the full SHA 060354aView commit details -
Test that Route53 region is optional with OpenAPI validation too
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for f6e028b - Browse repository at this point
Copy the full SHA f6e028bView commit details -
Make Route53 region optional (in openapi)
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 15cd934 - Browse repository at this point
Copy the full SHA 15cd934View commit details -
Signed-off-by: Nathan Baulch <nathan.baulch@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for a39748a - Browse repository at this point
Copy the full SHA a39748aView commit details
Commits on Sep 20, 2024
-
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for c274d1d - Browse repository at this point
Copy the full SHA c274d1dView commit details -
Update the Route53 region API documentation
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 9de6aa6 - Browse repository at this point
Copy the full SHA 9de6aa6View commit details -
Merge pull request #7290 from NathanBaulch/typos
Fix typos
Configuration menu - View commit details
-
Copy full SHA for 510b092 - Browse repository at this point
Copy the full SHA 510b092View commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for f17b436 - Browse repository at this point
Copy the full SHA f17b436View commit details -
Merge pull request #7278 from inteon/remove_deprecated_api_versions
Remove old API versions
Configuration menu - View commit details
-
Copy full SHA for 51f8f39 - Browse repository at this point
Copy the full SHA 51f8f39View commit details -
Merge pull request #7287 from wallrj/optional-aws-route53-region
Optional AWS Route53 region
Configuration menu - View commit details
-
Copy full SHA for 569f920 - Browse repository at this point
Copy the full SHA 569f920View commit details -
Test removeReqID with %w wrapped errors
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for deaf4d1 - Browse repository at this point
Copy the full SHA deaf4d1View commit details -
Merge pull request #7154 from jrcichra/webhook-ca-managed-by
Add managed-by label to webhook CA
Configuration menu - View commit details
-
Copy full SHA for caa24fc - Browse repository at this point
Copy the full SHA caa24fcView commit details -
Redact the RequestID in %w wrapped errors
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 422cc51 - Browse repository at this point
Copy the full SHA 422cc51View commit details -
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 13f9c94 - Browse repository at this point
Copy the full SHA 13f9c94View commit details -
Merge pull request #7291 from wallrj/route53-error-redact
Prevent aggressive Route53 retries caused by IRSA authentication failures by removing the Amazon Request ID from errors wrapped by the default credential cache
Configuration menu - View commit details
-
Copy full SHA for 900241b - Browse repository at this point
Copy the full SHA 900241bView commit details -
Log AWS SDK warnings and API requests at cert-manager debug level
Allows you to see which API endpoints are being used and which region is being used in the request signature. To help debug AWS Route53 problems in the field. Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for ce6153c - Browse repository at this point
Copy the full SHA ce6153cView commit details -
Merge pull request #7292 from wallrj/route53-debug-request-logging
Log AWS SDK warnings and API requests at cert-manager debug level
Configuration menu - View commit details
-
Copy full SHA for 63b158c - Browse repository at this point
Copy the full SHA 63b158cView commit details
Commits on Sep 21, 2024
-
Append cert-manager user-agent string to all AWS API requests
Including IMDS and STS requests. Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 5111a19 - Browse repository at this point
Copy the full SHA 5111a19View commit details -
Use context logger for Route53 operations
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 3707ce2 - Browse repository at this point
Copy the full SHA 3707ce2View commit details -
Merge pull request #7295 from wallrj/route53-user-agent-for-all-requests
Append cert-manager user-agent string to all AWS API requests
Configuration menu - View commit details
-
Copy full SHA for 193f318 - Browse repository at this point
Copy the full SHA 193f318View commit details -
Upgraded Go dependencies using https://github.com/oligot/go-mod-upgrade go-mod-upgrade make go-tidy make generate Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 9c5b699 - Browse repository at this point
Copy the full SHA 9c5b699View commit details
Commits on Sep 22, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b91c777 - Browse repository at this point
Copy the full SHA b91c777View commit details -
Merge pull request #7298 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for b76e982 - Browse repository at this point
Copy the full SHA b76e982View commit details -
Merge pull request #7296 from wallrj/route53-contextual-logging
Use context logger for Route53 operations
Configuration menu - View commit details
-
Copy full SHA for a0b29a2 - Browse repository at this point
Copy the full SHA a0b29a2View commit details -
Merge pull request #7297 from wallrj/go-mod-upgrade
go-mod-upgrade
Configuration menu - View commit details
-
Copy full SHA for 8276d84 - Browse repository at this point
Copy the full SHA 8276d84View commit details
Commits on Sep 24, 2024
-
Enable the WatchList (Streaming Lists) feature
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 9ed80cf - Browse repository at this point
Copy the full SHA 9ed80cfView commit details -
Merge pull request #7175 from wallrj/3748-enable-watchlist-streaming-…
…lists Reduce load on the Kubernetes API server and reduce the peak memory use of the cert-manager components by enabling the use of the WatchList (Streaming Lists) feature
Configuration menu - View commit details
-
Copy full SHA for 81bd1c5 - Browse repository at this point
Copy the full SHA 81bd1c5View commit details
Commits on Sep 25, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 5747ea2 - Browse repository at this point
Copy the full SHA 5747ea2View commit details -
fix copyloopvar linter, removing copies that are no longer necessary
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 8d7c8f0 - Browse repository at this point
Copy the full SHA 8d7c8f0View commit details -
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 3651ab7 - Browse repository at this point
Copy the full SHA 3651ab7View commit details -
add support for testing k8s 1.31 with kind 0.24.0
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for d6097ee - Browse repository at this point
Copy the full SHA d6097eeView commit details -
Merge pull request #7300 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 8d61c8e - Browse repository at this point
Copy the full SHA 8d61c8eView commit details -
Merge pull request #7302 from SgtCoDFish/k8s-1.31
Add support for Kubernetes 1.31 in kind v0.24
Configuration menu - View commit details
-
Copy full SHA for 9fa1112 - Browse repository at this point
Copy the full SHA 9fa1112View commit details -
Always fall back on the ambient region
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 7c5df3a - Browse repository at this point
Copy the full SHA 7c5df3aView commit details -
Use regional STS endpoints for the dedicated STS client, when a Role …
…or WebIdentityToken are supplied in the Issuer Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 8fcd13b - Browse repository at this point
Copy the full SHA 8fcd13bView commit details
Commits on Sep 26, 2024
-
Merge pull request #7299 from wallrj/route53-ambient-region
Route53 DNS01 Solver: Always fall back on the ambient region
Configuration menu - View commit details
-
Copy full SHA for f3b2a98 - Browse repository at this point
Copy the full SHA f3b2a98View commit details -
Fix possible OOM failures in the makestage Google Cloud Build
By reducing the make parallelism. Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 59c558b - Browse repository at this point
Copy the full SHA 59c558bView commit details -
Use a better supported machine type
N1_HIGHCPU_32 is no longer listed in the table of supported GCB machine types, but there is the following foot note in the documentation: > Cloud Build continues to offer n1-highcpu-8 and n1-highcpu-32 machine types. They are offered at the same price as e2-highcpu-8 and e2-highcpu-32 https://cloud.google.com/build/pricing Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 25c7ffa - Browse repository at this point
Copy the full SHA 25c7ffaView commit details -
Merge pull request #7308 from wallrj/fix-makestage-oom-failures
Fix makestage OOM failures
Configuration menu - View commit details
-
Copy full SHA for f2c262c - Browse repository at this point
Copy the full SHA f2c262cView commit details
Commits on Oct 1, 2024
-
Revert "Reduce load on the Kubernetes API server and reduce the peak …
…memory use of the cert-manager components by enabling the use of the WatchList (Streaming Lists) feature" Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 99498f3 - Browse repository at this point
Copy the full SHA 99498f3View commit details -
Merge pull request #7315 from wallrj/revert-7175-3748-enable-watchlis…
…t-streaming-lists Revert "Reduce load on the Kubernetes API server and reduce the peak memory use of the cert-manager components by enabling the use of the WatchList (Streaming Lists) feature"
Configuration menu - View commit details
-
Copy full SHA for b56ac27 - Browse repository at this point
Copy the full SHA b56ac27View commit details -
Add extraEnv to webhook, cainjector, and startupapicheck
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 28f2fa5 - Browse repository at this point
Copy the full SHA 28f2fa5View commit details -
make generate-helm-schema generate-helm-docs
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 617f29b - Browse repository at this point
Copy the full SHA 617f29bView commit details -
Update deployments and startupapi Job
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 2543831 - Browse repository at this point
Copy the full SHA 2543831View commit details -
Merge pull request #7317 from wallrj/7316-extraenv-cainjector-webhook
Allow extra environment variables to be added to cainjector, webhook and startupapicheck
Configuration menu - View commit details
-
Copy full SHA for 0780948 - Browse repository at this point
Copy the full SHA 0780948View commit details
Commits on Oct 2, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 788501d - Browse repository at this point
Copy the full SHA 788501dView commit details -
Merge pull request #7321 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for ee36b5d - Browse repository at this point
Copy the full SHA ee36b5dView commit details -
Signed-off-by: Richard Wall <richard.wall@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 5210d2a - Browse repository at this point
Copy the full SHA 5210d2aView commit details -
Merge pull request #7323 from wallrj/bump-base-images
make update-base-images
Configuration menu - View commit details
-
Copy full SHA for 4830066 - Browse repository at this point
Copy the full SHA 4830066View commit details
Commits on Oct 5, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 2eb8877 - Browse repository at this point
Copy the full SHA 2eb8877View commit details -
Merge pull request #7336 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 6f7989d - Browse repository at this point
Copy the full SHA 6f7989dView commit details
Commits on Oct 7, 2024
-
BUGFIX: use correct resource namespace for Cluster Issuers
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7d1481d - Browse repository at this point
Copy the full SHA 7d1481dView commit details -
add ACME ClusterIssuer resource namespace test
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 956e53b - Browse repository at this point
Copy the full SHA 956e53bView commit details -
Merge pull request #7339 from inteon/bugfix_cluster_issuer_secrets
BUGFIX: use correct resource namespace for Cluster Issuers
Configuration menu - View commit details
-
Copy full SHA for e2c59bf - Browse repository at this point
Copy the full SHA e2c59bfView commit details -
update schema validation for minAvailable and maxAvailable to accept …
…both string and integer values Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 366b7af - Browse repository at this point
Copy the full SHA 366b7afView commit details -
Merge pull request #7343 from inteon/allow_string_or_int
BUGFIX: Update schema validation to accept both string and integer values
Configuration menu - View commit details
-
Copy full SHA for 59b6429 - Browse repository at this point
Copy the full SHA 59b6429View commit details -
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 96411a9 - Browse repository at this point
Copy the full SHA 96411a9View commit details -
Merge pull request #7346 from cert-manager/self-upgrade-master
[CI] Self-upgrade merging self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 4c353f1 - Browse repository at this point
Copy the full SHA 4c353f1View commit details
Commits on Oct 8, 2024
-
Helm: add enabled to json schema
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for bd1d076 - Browse repository at this point
Copy the full SHA bd1d076View commit details -
Helm chart: fix documentation for service accounts annotations
Signed-off-by: jordanp <jordan@rezel.net>
Configuration menu - View commit details
-
Copy full SHA for 871a189 - Browse repository at this point
Copy the full SHA 871a189View commit details
Commits on Oct 9, 2024
-
Merge pull request #7351 from JordanP/helm-chart-values-documentation
Helm chart: fix documentation for service accounts annotations
Configuration menu - View commit details
-
Copy full SHA for fee64aa - Browse repository at this point
Copy the full SHA fee64aaView commit details -
Merge pull request #7350 from inteon/add_enabled
Helm: add enabled to json schema
Configuration menu - View commit details
-
Copy full SHA for 680e856 - Browse repository at this point
Copy the full SHA 680e856View commit details -
Chart docs: Add enableGatewayAPI upd feat gates
This commit adds the `enableGatewayAPI` parameter to the chart config example. It also updates the feature gate list with their default values. Signed-off-by: Adolfo García Veytia (puerco) <puerco@stacklok.com>
Configuration menu - View commit details
-
Copy full SHA for ed11841 - Browse repository at this point
Copy the full SHA ed11841View commit details -
make vendor-go generate-helm-schema
Signed-off-by: Adolfo García Veytia (puerco) <puerco@stacklok.com>
Configuration menu - View commit details
-
Copy full SHA for b89a0e5 - Browse repository at this point
Copy the full SHA b89a0e5View commit details
Commits on Oct 10, 2024
-
Merge pull request #7354 from puerco/chart-gatewaty-api
Chart docs: Add enableGatewayAPI feature gates
Configuration menu - View commit details
-
Copy full SHA for 5e2b1c1 - Browse repository at this point
Copy the full SHA 5e2b1c1View commit details
Commits on Oct 11, 2024
-
Merge pull request #7240 from inteon/use_go_1.23_iterators
Use new go 1.23 iterators
Configuration menu - View commit details
-
Copy full SHA for 129ce79 - Browse repository at this point
Copy the full SHA 129ce79View commit details -
fix: don't create certificaterequests while being deleted
Signed-off-by: Adam Talbot <adamtalbot93@googlemail.com>
Configuration menu - View commit details
-
Copy full SHA for 49482f9 - Browse repository at this point
Copy the full SHA 49482f9View commit details -
chore: e2e tests to ensure certificaterequests and secrets are not cr…
…eated when a certificate is deleted Signed-off-by: Adam Talbot <adamtalbot93@googlemail.com>
Configuration menu - View commit details
-
Copy full SHA for cb4b53b - Browse repository at this point
Copy the full SHA cb4b53bView commit details
Commits on Oct 14, 2024
-
Merge pull request #7361 from ThatsMrTalbot/fix/dont-create-certifica…
…te-requests-while-being-deleted fix: don't create certificaterequests while being deleted
Configuration menu - View commit details
-
Copy full SHA for 71f43d5 - Browse repository at this point
Copy the full SHA 71f43d5View commit details -
remove unused pod helper functions
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 589dca7 - Browse repository at this point
Copy the full SHA 589dca7View commit details -
fix log interface signature mismatch
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for b7de552 - Browse repository at this point
Copy the full SHA b7de552View commit details -
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d379954 - Browse repository at this point
Copy the full SHA d379954View commit details
Commits on Oct 15, 2024
-
Run 'make upgrade-klone' and 'make generate'
Signed-off-by: Tim Ramlot <42113979+inteon@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 5e61f4a - Browse repository at this point
Copy the full SHA 5e61f4aView commit details -
Merge pull request #7366 from cert-manager/self-upgrade-master
[CI] Self-upgrade merging self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for ab6d8fb - Browse repository at this point
Copy the full SHA ab6d8fbView commit details -
add IPv6 example for recursive DNS arg
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 1a0f0f9 - Browse repository at this point
Copy the full SHA 1a0f0f9View commit details -
Merge pull request #7367 from SgtCoDFish/ipv6-recursive-dns
add IPv6 example for recursive DNS arg
Configuration menu - View commit details
-
Copy full SHA for 1be0dfc - Browse repository at this point
Copy the full SHA 1be0dfcView commit details
Commits on Oct 16, 2024
-
Use different hash algorithms for larger RSA keys
See also #7357 A US DoD document [1] states that: > Effective immediately, all Public Key enabled commercial-off-the-shelf > software and Public Key enabled Open-Source software integrations [...] > must support at least RSA-3072 (4096 is preferred) and SHA-384. cert-manager already supports large RSA keys - that's no problem. But we always use SHA256 with all RSA keys currently; this commit changes that so we use SHA512 for RSA keys 4096 bits and above, or else SHA384 for RSA keys 3072 bits and above, or else SHA256. We discussed in standups / in the issue how to roll this out, and the consensus so far has been to roll this out unilaterally. Albeit we don't have data to support our assumption, we believe there won't be any huge compatibility problems from using this approach. One potential issue is that SHA512 can take (much) longer on some low powered 32-bit platforms (think older Raspberry Pis). We decided that the risk of slowdown there isn't worth delaying the rollout of this. Plus, people using those devices always have the option of using RSA-2048 or else ECDSA / Ed25519. [1]: https://dl.dod.cyber.mil/wp-content/uploads/pki-pke/pdf/unclass-memo_dodcryptoalgorithms.pdf Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 6e92072 - Browse repository at this point
Copy the full SHA 6e92072View commit details -
Merge pull request #7368 from SgtCoDFish/ca-issuer-sig-algo
Use different hash algorithms for larger RSA keys
Configuration menu - View commit details
-
Copy full SHA for 59abb31 - Browse repository at this point
Copy the full SHA 59abb31View commit details -
Merge pull request #7363 from inteon/remove_unused_functions
Remove unused test functions
Configuration menu - View commit details
-
Copy full SHA for e1a1ea9 - Browse repository at this point
Copy the full SHA e1a1ea9View commit details
Commits on Oct 21, 2024
-
remove use of magic numbers when validating RSA key sizes
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for f4f3ce4 - Browse repository at this point
Copy the full SHA f4f3ce4View commit details -
panic on errors in vault setup, use pki pkg where available
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for bcd2756 - Browse repository at this point
Copy the full SHA bcd2756View commit details -
switch to math/rand/v2 for jitter
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for bf35e91 - Browse repository at this point
Copy the full SHA bf35e91View commit details -
Merge pull request #7381 from SgtCoDFish/randtweaks
Cleanup key gen / RSA key sizes
Configuration menu - View commit details
-
Copy full SHA for 0a8268e - Browse repository at this point
Copy the full SHA 0a8268eView commit details
Commits on Oct 25, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 7a5d75a - Browse repository at this point
Copy the full SHA 7a5d75aView commit details -
Merge pull request #7387 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for e8ce708 - Browse repository at this point
Copy the full SHA e8ce708View commit details -
add tenantID option to azureDNS managedIdentity
Signed-off-by: Jochen Richter <jochenrichter84@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for c951974 - Browse repository at this point
Copy the full SHA c951974View commit details -
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 15cc475 - Browse repository at this point
Copy the full SHA 15cc475View commit details -
Merge pull request #7376 from jochenrichter/managed_identity_tenant_id
add tenantID option to azureDNS managedIdentity
Configuration menu - View commit details
-
Copy full SHA for ec1f6e1 - Browse repository at this point
Copy the full SHA ec1f6e1View commit details
Commits on Nov 1, 2024
-
Do not propagate applyset labels
Resources with applyset labels will be pruned, which is problematic. Instead of a generic annotation to control label propagation, the applyset labels are always excluded. This should be a good middleground whilst an API for doing this in a more generic way is discussed. The label should not ever be propagated, and so is a safe default. Fixes: #7306 Signed-off-by: Thomas Way <thomas@6f.io>
Configuration menu - View commit details
-
Copy full SHA for 4de5570 - Browse repository at this point
Copy the full SHA 4de5570View commit details
Commits on Nov 5, 2024
-
Merge pull request #7394 from uhthomas/7306
Do not propagate applyset labels
Configuration menu - View commit details
-
Copy full SHA for 1c2ee41 - Browse repository at this point
Copy the full SHA 1c2ee41View commit details -
security: Add functions to limit max PEM sizes allowable
Includes a lot of comments explaining how the maxima were calculated. This is _very_ conservative, and assumes we're dealing with RSA keys twice the size of what we actually allow as a maximum. From running the included benchmark it seems the pathological runtime is about 13617196ns (13ms) on an M2 Max which seems acceptable. Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for 3a4c9eb - Browse repository at this point
Copy the full SHA 3a4c9ebView commit details -
security: remove calls to pem.Decode in non-test code
Signed-off-by: Ashley Davis <ashley.davis@venafi.com>
Configuration menu - View commit details
-
Copy full SHA for f22f78c - Browse repository at this point
Copy the full SHA f22f78cView commit details
Commits on Nov 6, 2024
-
Merge pull request #7400 from SgtCoDFish/pem-inputs
Restrict max size of PEM inputs
Configuration menu - View commit details
-
Copy full SHA for e5d62ad - Browse repository at this point
Copy the full SHA e5d62adView commit details
Commits on Nov 8, 2024
-
BOT: run 'make upgrade-klone' and 'make generate'
Signed-off-by: cert-manager-bot <cert-manager-bot@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 25911fa - Browse repository at this point
Copy the full SHA 25911faView commit details -
Merge pull request #7410 from cert-manager/self-upgrade-master
[CI] Merge self-upgrade-master into master
Configuration menu - View commit details
-
Copy full SHA for 63f83c9 - Browse repository at this point
Copy the full SHA 63f83c9View commit details